HireFlow
Data Processing Agreement
Data Processing Agreement (verwerkersovereenkomst) for HireFlow agency customers.
Version 2026-09-06 · Effective date 2026-09-06
1. Parties and relationship
This Data Processing Agreement (“DPA”) is between the HireFlow business customer (the “Controller” / “Customer”) and Appollo Lab, Hoornstraat 10, 5402 HP Uden, The Netherlands, KVK 96983299, VAT NL005241718B76 (the “Processor”).
This DPA applies where Appollo Lab processes personal data on behalf of the Customer in connection with the HireFlow platform under the HireFlow Terms or another written agreement between the parties (the “Main Agreement”). Publishing this DPA does not by itself execute a contract; it becomes binding when incorporated by the Main Agreement, a written order, or another express acceptance mechanism agreed by the parties. Viewing or downloading this page is not an electronic signature.
2. Scope and definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “sub-processor”, and “personal data breach” have the meanings in the EU General Data Protection Regulation (GDPR) and, where applicable, Dutch implementing law. “HireFlow” means the recruitment software operated by Appollo Lab.
3. Roles
For candidate and recruitment personal data processed through HireFlow on the Customer’s behalf, the Customer is normally the controller and Appollo Lab is normally the processor. The Customer determines the purposes and means of that recruitment processing and its lawful basis.
Appollo Lab may separately act as an independent controller for its own business processing (for example account administration, contractual administration, service security, operational records, legal compliance, and direct Customer communications). That independent controller processing is outside the scope of processor instructions under this DPA and is described in the HireFlow Privacy Statement.
4. Processing schedule (Annex A)
- Subject matter: hosting and operation of HireFlow for the Customer’s recruitment workflows.
- Duration: for the term of the Main Agreement and any post-termination return/deletion period.
- Nature: collection, storage, organisation, retrieval, transmission, erasure, and related SaaS processing.
- Purposes: providing the platform features the Customer uses (jobs, applications, CV/email intake, recruiter collaboration, optional AI suggestions, communications tooling).
- Data subjects: candidates and applicants; Customer staff/users; other individuals whose data the Customer submits.
- Personal data categories: identity and contact details; application/profile content; CV and supporting files; inbound email content/attachments; recruiter notes and workflow data; technical logs as needed to operate the service. HireFlow does not require a Dutch BSN number as a structured product field. CVs may incidentally contain additional identifiers supplied by individuals.
5. Controller instructions
The Processor will process personal data only on documented instructions from the Controller, including processing inherent in the Customer’s use of HireFlow features, unless required to do otherwise by Union or Member State law (in which case the Processor informs the Controller where legally permitted). The Customer is responsible for the lawfulness of its instructions and of personal data it uploads or causes to be processed.
6. Processor obligations
The Processor will: (a) ensure persons authorised to process the personal data are committed to confidentiality; (b) implement appropriate technical and organisational measures (Annex B); (c) respect the conditions for engaging sub-processors (Section 8); (d) assist the Controller with data-subject requests, security, breach notification, and DPIA/consultation obligations, taking into account the nature of processing and information available to the Processor; (e) delete or return personal data after the end of processing services as set out in Section 11; and (f) make available information necessary to demonstrate compliance with this DPA and allow audits as set out in Section 12.
7. Security measures (Annex B)
Taking into account the state of the art, costs, and the nature/scope/context of processing, Appollo Lab applies reasonable measures appropriate for a B2B SaaS recruitment platform, including:
- Access control and authentication for agency portals
- Role/permission scoping within an agency workspace (tenant isolation in standard product interfaces)
- Transport security (HTTPS) for public application traffic
- Secrets handled via server environment configuration (not committed to the application repository)
- Operational logging and agency-scoped audit events for selected actions (for example DSAR/erasure)
- Scheduled backups of database and media with defined retention on the production host
- External uptime monitoring of public health endpoints and privacy-minimised exception monitoring where configured
- Data minimisation practices such as privacy scrubbing for exception telemetry and size limits on AI CV input (truncation is not anonymisation)
No system is perfectly secure. This Annex does not promise absolute security, uninterrupted availability, or zero data loss.
8. Sub-processors
The Controller provides general written authorisation for Appollo Lab to engage the sub-processors listed in the public HireFlow Subprocessor Register, as updated from time to time. View the Subprocessor Register.
Appollo Lab will maintain a versioned public register. For material additions or replacements of sub-processors that process Customer personal data under this DPA, Appollo Lab will provide notice by email to the Customer’s registered account or billing/admin contact (or another address the Customer designates). There is no automated in-product subprocessor notification system in V1. The Customer may object on reasonable data-protection grounds within thirty (30) days of notice; the parties will discuss alternatives in good faith. If no reasonable alternative is available, either party may terminate the affected processing services as permitted under the Main Agreement.
9. Data-subject requests
Taking into account the nature of processing, Appollo Lab will assist the Customer by appropriate technical and organisational measures, insofar as possible, for the Customer’s obligation to respond to data-subject requests. HireFlow provides agency-scoped DSAR export and erasure tooling for authorised Customer users. Where a data subject contacts Appollo Lab directly about Customer-controlled data, Appollo Lab will redirect or cooperate with the Customer and will not independently decide the request as if it were the recruitment controller.
10. Personal-data breaches
Appollo Lab will notify the Customer without undue delay after becoming aware of a personal-data breach affecting personal data processed under this DPA, and will provide information reasonably available to assist the Customer with its notification obligations. This DPA does not invent fixed hourly SLA response times beyond “without undue delay.”
11. Return and deletion
During the subscription term, the Customer may use product tooling (including DSAR export and agency-scoped candidate erasure) to retrieve or erase data. Automatic purge of all candidate data is not implemented in the current V1 product. After termination of HireFlow services for the Customer, Appollo Lab will, at the Customer’s written election and within a reasonable period, return available Customer personal data in a commonly used electronic format or delete it from live systems, except where retention is required by law or needed for Appollo Lab’s independent controller purposes (for example security, billing, or dispute records). Full self-serve agency offboarding/deletion is not fully productized; post-termination return/deletion may require manual operational handling by Appollo Lab. Historical backups may retain data for a limited retention window after live deletion.
12. Audit and information rights
Upon reasonable written request, Appollo Lab will make available information reasonably necessary to demonstrate compliance with this DPA. Audits are limited to once per twelve (12) months unless required by a supervisory authority or following a personal-data breach, and must be conducted with reasonable notice, during business hours, without disrupting operations, and subject to confidentiality. Appollo Lab may satisfy audit requests with current documentation, questionnaires, or equivalent evidence where appropriate.
13. International transfers
Where processing involves a transfer of personal data outside the EEA, Appollo Lab will ensure a lawful transfer mechanism is in place for the relevant relationship (for example adequacy, standard contractual clauses, or another valid tool). Exact mechanisms and provider regions depend on provider contracts and operational verification and are summarised conservatively in the Subprocessor Register. Unsupported transfer claims are not made in this DPA.
14. DPIA and authority cooperation
Taking into account the nature of processing and information available, Appollo Lab will assist the Customer with data-protection impact assessments and prior consultations with supervisory authorities where required for processing under this DPA.
15. Liability and hierarchy
Liability under this DPA is subject to the limitations and exclusions in the Main Agreement, except where prohibited by mandatory law. If there is a conflict between this DPA and the Main Agreement on data-protection processor topics, this DPA prevails for those topics. Mandatory applicable law prevails over conflicting contractual wording.
16. Governing law
This DPA is governed by the laws of the Netherlands, without prejudice to mandatory data-protection rules. Courts of the Netherlands have jurisdiction, subject to mandatory applicable law. No specific court is nominated beyond that general position.
17. Contact
- Legal operator: Appollo Lab
- Address: Hoornstraat 10, 5402 HP Uden, The Netherlands
- KVK: 96983299
- VAT ID: NL005241718B76
- Privacy: privacy@hireflowjobs.com
- Legal: legal@hireflowjobs.com
This DPA is an internal self-reviewed V1 production publication aligned to Appollo Lab’s approved business decisions. It is not external legal-counsel approval and is not a claim of complete regulatory certification.